An engineer is working on a switch and must tag packets with SGT values such that it learns via SXP. Which command must be entered to meet this requirement?
A. ip source guard
B. ip dhcp snooping
C. ip device tracking maximum
D. ip arp inspection
A network security administrator needs a web authentication configuration when a guest user connects to the network with a wireless connection using these steps:
An initial MAB request is sent to the Cisco ISE node.
Cisco ISE responds with a URL redirection authorization profile if the user's MAC address is unknown in the endpoint identity store.
The URL redirection presents the user with an AUP acceptance page when the user attempts to go to any URL.
Which authentication must the administrator configure on Cisco ISE?
A. device registration WebAuth
B. WLC with local WebAuth
C. wired NAD with local WebAuth
D. NAD with central WebAuth
An engineer is adding a new network device to be used with 802.1X authentication. After configuring the device, the engineer notices that no endpoints that connect to the switch are able to authenticate. What is the problem?
A. The command dot1x system-auth-control is not configured on the switch.
B. The switch's supplicant is unable to establish a connection to Cisco ISE.
C. The command dot1x critical vlan 40 is not configured on the switch ports.
D. The endpoint firewalls are blocking the EAPoL traffic.
An enterprise uses a separate PSN for each of its four remote sites. Recently, a user reported receiving an "EAP-TLS authentication failed" message when moving between remote sites. Which configuration must be applied on Cisco ISE?
A. Use a third-party certificate on the network device.
B. Add the device to all PSN nodes in the deployment.
C. Renew the expired certificate on one of the PSN.
D. Configure an authorization profile for the end users.
An engineer is starting to implement a wired 802.1X project throughout the campus. The task is for failed authentication to be logged to Cisco ISE and also have a minimal impact on the users. Which command must the engineer configure?
A. authentication open
B. pae dot1x enabled
C. authentication host-mode multi-auth
D. monitor-mode enabled
A network engineer is in the predeployment discovery phase of a Cisco ISE deployment and must discover the network. There is an existing NMS in the network. Which type of probe must be configured to gather the information?
A. SNMP
B. NMAP
C. NetFlow
D. RADIUS
An engineer must organize endpoints in a Cisco ISE identity management store to improve the operational management of IP phone endpoints. The endpoints must meet these requirements:
1.
classify endpoints for finance, sales, and marketing departments
2.
tag each endpoint as profiled
Which action organizes the endpoints?
A. Add a tag for the endpoints of each department and use the identity group filter.
B. Create an endpoint identity group for each department with the profiled parent group.
C. Add a tag for the endpoints of each department and add an endpoint to profiled group.
D. Create an endpoint identity group for each department with the IP phone parent group.
A network engineer must remove a device that has been allowlisted. How should the engineer remove it manually on Cisco ISE?
A. Administration > Identity Management > Endpoint Identity Groups > Profiled
B. Administration > Identity Management > Groups > Endpoint Identity Groups
C. Administration > Identity Management > Groups > Endpoint Identity Groups > Profiled
D. Administration > Identity Management > Endpoint Identity Groups
Which file setup method is supported by ZTP on physical appliances?
A. cfg
B. iso
C. img
D. ova
What is configured to enforce the blocklist permissions and deny access to clients in the blocklist to protect against a lost or stolen device obtaining access to the network?
A. My Devices portal
B. blocklist portal
C. Authentication rule
D. Authorization rule
Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 300-715 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.